Multi-Factor Authentication (MFA) Explained for Small Businesses
Multi-factor authentication (MFA) asks for a second proof of identity on top of your password, so a stolen password alone is not enough to break in. It blocks the vast majority of account takeovers. This guide explains the main types — app codes, SMS and passkeys — which to trust, and how to roll MFA out across your team without the chaos.
Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.
What multi-factor authentication actually is
Multi-factor authentication (MFA) is a simple idea with an awkward name. It just means that logging in takes more than a password. After you type your password, the service asks for a second proof that you are really you — usually a code from an app on your phone, or a tap to approve.
Think of it like a bank card. The card on its own is not enough; you also need the PIN. MFA does the same thing for your online accounts. A stolen password on its own becomes useless, because the criminal cannot produce that second proof.
The three “factors” are usually described as:
- Something you know — your password or PIN.
- Something you have — your phone, an app, or a physical security key.
- Something you are — your fingerprint or face.
MFA simply combines two of these instead of relying on one.
Why MFA stops most account takeovers
Most break-ins do not involve clever hacking. They involve a criminal who already has a working password — bought from a data breach, guessed because it was reused, or captured through a phishing email. Once they have it, they log in as you.
MFA breaks that chain. Even with the correct password, the attacker hits a second door they cannot open. The National Cyber Security Centre (NCSC) recommends MFA precisely because it blocks the overwhelming majority of these routine attacks. It is also a requirement of the government-backed Cyber Essentials scheme, so turning it on moves you towards a recognised standard as well.
The accounts worth protecting first are the ones that unlock everything else:
- Your email (because password resets for other services land there)
- Microsoft 365 or Google Workspace
- Online banking and accounting software
- Your password manager
- Any remote access to your systems
App codes vs SMS vs passkeys
Not all MFA is equally strong. Here is how the common options compare in plain terms.
Text message (SMS) codes
You receive a code by text and type it in. This is the most familiar method and much better than nothing. The weakness is that phone numbers can be stolen or redirected by criminals, and codes can sometimes be intercepted. Use SMS where it is the only option, but do not rely on it for your most important accounts.
Authenticator apps
An app on your phone — such as Microsoft Authenticator, Google Authenticator, or the one built into a password manager — generates a fresh six-digit code every 30 seconds, or sends a “approve this login” prompt. The codes never travel across the phone network, so they cannot be intercepted the way texts can. For most small businesses, an authenticator app is the sensible default.
Passkeys
Passkeys are the newest and strongest option, and they are quietly replacing passwords altogether. Instead of a code, your device proves who you are using your fingerprint, face, or PIN. There is nothing to type, nothing to intercept, and nothing a phishing site can trick out of you — which is what makes passkeys so resistant to fraud. Major services including Microsoft, Google and Apple now support them. Expect to use passkeys far more over the next couple of years.
If you use a password manager to store logins across your team, choosing one that also handles MFA codes and passkeys keeps everything in one place. Proton Pass, part of the privacy-focused Proton suite that we use ourselves, does exactly that. For a wider comparison, see our guide to the best password manager for a small business.
Rolling MFA out across your team
Turning on MFA for yourself takes five minutes. Rolling it out across a team without complaints takes a little planning. Here is a straightforward approach.
- Start with the crown jewels. Enable MFA on email and Microsoft 365 or Google first. These protect the most and cause the least disruption.
- Choose one method as your standard. Pick an authenticator app (or passkeys where supported) so everyone follows the same process and your support is consistent.
- Set up recovery before you need it. Save the backup codes each service provides, and store them somewhere safe and offline. This is your way back in if a phone is lost or replaced.
- Brief the team simply. Explain that the extra tap stops criminals who already have their password. Framed as protection rather than hassle, most people accept it quickly.
- Make it mandatory, not optional. In Microsoft 365 and Google Workspace, an administrator can require MFA for everyone. Left optional, the accounts that skip it are the ones that get breached.
Expect a week or two of small questions, then it becomes second nature. The one-off effort is tiny compared with the cost of a hijacked email account sending invoice fraud to your clients.
The bottom line
MFA is the highest-value, lowest-cost security step most small businesses can take. It neutralises stolen passwords, satisfies part of Cyber Essentials, and takes minutes per account to set up. Prefer an authenticator app or passkeys over text codes, protect your email and admin accounts first, and make it a requirement rather than a suggestion.
Want this handled properly across your business, alongside the rest of your defences? Learn more about our cyber-security services, read our Cyber Essentials explainer, or get in touch for a no-pressure conversation about where to start.
Frequently asked questions
Is MFA really necessary if we have strong passwords?
Yes. Strong passwords help, but they still leak in data breaches, get reused across sites, or get handed over during phishing attacks. MFA is a separate barrier, so even a correct password is not enough to get in on its own. It is one of the single most effective things a small business can do, which is why it appears in the Cyber Essentials scheme.
What is the difference between MFA and 2FA?
They mean almost the same thing in everyday use. 2FA (two-factor authentication) means exactly two proofs — usually your password plus one more. MFA (multi-factor authentication) is the broader term for two or more factors. If a supplier offers either, turn it on; the label matters far less than the protection.
What happens if I lose my phone with the authenticator app on it?
This is why backup codes matter. When you set up MFA, most services give you a set of one-time recovery codes — save them somewhere safe and offline. Many authenticator apps and password managers can also sync your codes securely to a new device. Set up a recovery method before you need it, not after.
Are text-message codes safe enough?
SMS codes are far better than no MFA at all, so use them if that is all a service offers. But they are the weakest option, because criminals can hijack phone numbers or intercept messages. Where you have the choice, prefer an authenticator app or a passkey for anything important — email, banking, and your Microsoft 365 or Google accounts.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.